Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-18599

Опубликовано: 12 июн. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-18599: p11-kit security update (MODERATE)

[0.26.2-1]

  • Rebase to 0.26.2 Resolves: RHEL-147825

[0.26.1-1]

  • Rebase to 0.26.1 Resolves: RHEL-139075, RHEL-118361, RHEL-126132

[0.25.10-1]

  • Update to new upstream release 0.25.10 Resolves: RHEL-115453

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

p11-kit

0.26.2-1.el9

p11-kit-client

0.26.2-1.el9

p11-kit-devel

0.26.2-1.el9

p11-kit-server

0.26.2-1.el9

p11-kit-trust

0.26.2-1.el9

Oracle Linux x86_64

p11-kit

0.26.2-1.el9

p11-kit-client

0.26.2-1.el9

p11-kit-devel

0.26.2-1.el9

p11-kit-server

0.26.2-1.el9

p11-kit-trust

0.26.2-1.el9

Связанные CVE

Связанные уязвимости

CVSS3: 5.3
ubuntu
4 месяца назад

A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. This issue may cause an application level denial of service or other unpredictable system states.

CVSS3: 5.3
redhat
6 месяцев назад

A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. This issue may cause an application level denial of service or other unpredictable system states.

CVSS3: 5.3
nvd
4 месяца назад

A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. This issue may cause an application level denial of service or other unpredictable system states.

msrc
4 месяца назад

P11-kit: p11-kit: null dereference via c_derivekey with specific null parameters

CVSS3: 5.3
debian
4 месяца назад

A flaw was found in p11-kit. A remote attacker could exploit this vuln ...